Certified Information Systems Auditor (CISA) — Question 448
Which of the following activities would allow an IS auditor to maintain independence while facilitating a control self-assessment (CSA)?
Answer options
- A. Implementing the remediation plan
- B. Developing the remediation plan
- C. Developing the CSA questionnaire
- D. Partially completing the CSA
Correct answer: C
Explanation
The correct answer is C because developing the CSA questionnaire allows the auditor to gather information without influencing the results. Options A and B involve active participation in remediation, which could compromise independence, while D suggests an incomplete process that does not align with maintaining objectivity.